Automatically translated.View original post

Other ones can't be uploaded, but this one can't be uploaded.

Microsoft has gradually started releasing a new set of Secure Boot certificate updates; after the original certificate, in use since 2011, is expiring in mid-2026, marking a major security update to the Windows system.

.

Secure Boot serves to authenticate the software from the power-up stage, ensuring that only the operating system or certified code can boot up. As the original certificate nears expiration, Microsoft issues a new set of 2023 certificates, replacing it, to prevent over-aging encryption keys from becoming system weaknesses and continuing the platform's security standards.

.

The good news is that most of the new PCs or hardware that have been released since 2024 are already with a 2023 certificate, so no further action is required. This group is hardly affected by the expiration of the 2011 certificate.

.

This update is gradually released through Windows Update on a regular cycle. Ordinary users do little more, just install regular system updates, but some devices may need to receive firmware or BIOS / UEFI updates from additional hardware manufacturers to fully support the new certificate.

.

The point to be aware of is that for Windows 11 users who forcibly open Secure Boot is a system requirement. If this new set of certificates is not installed, it may be vulnerable to future problems, including cases where the machine cannot boot normally, while Windows 10 users who do not have Secure Boot enabled will not be directly affected.

.

But for Windows 10 users who have opened Secure Boot, especially those outside the main support range, consider joining the Extended Security Updates (ESU) program to receive security updates and install a new set of certificates before the expiration deadline to avoid the risk of subsequent problems.

.

Source: Neowin

# IT should know # IT News # Includes IT matters # IT

2/23 Edited to

... Read moreSecure Boot คือฟีเจอร์ความปลอดภัยใน UEFI (แทน BIOS แบบเก่า) ที่ทำหน้าที่ “ตรวจลายเซ็นดิจิทัล” ของไฟล์/ตัวโหลดระบบตั้งแต่เริ่มเปิดเครื่อง พูดง่าย ๆ คือมันคัดกรองตั้งแต่หน้าประตูบ้านว่า โค้ดที่กำลังจะถูกโหลดเพื่อบูต Windows เป็นของแท้และได้รับการรับรองหรือไม่ เพื่อกันพวก bootkit/rootkit ที่ชอบแทรกตัวก่อนระบบปฏิบัติการเริ่มทำงาน (ซึ่งปกติแอนตี้ไวรัสตามไม่ค่อยทัน) หลายคนสงสัยว่าแล้วทำไมช่วงนี้ถึงมีข่าว “ต้องอัปเดต Secure Boot” คำตอบคือ Secure Boot อาศัย “ใบรับรอง/คีย์” (เช่น KEK – Key Exchange Key) เพื่อใช้ยืนยันความถูกต้องของซอฟต์แวร์ตอนบูต แต่ใบรับรองเดิมที่ใช้มาตั้งแต่ปี 2011 กำลังจะหมดอายุช่วงกลางปี 2026 Microsoft เลยทยอยปล่อยใบรับรองชุดใหม่ (ปี 2023) ผ่าน Windows Update เพื่อให้เครื่องยังบูตได้ปกติและคงมาตรฐานความปลอดภัยไว้ จากที่เช็กเครื่องตัวเอง จุดสังเกตที่เจอบ่อยคือใน Windows Update อาจมีอัปเดตที่เกี่ยวกับ Secure Boot/KEK โผล่มา และมีคำเตือนทำนอง “ไม่อัปเดต ระวังเปิดไม่ติด” แม้ตอนนี้อาจยังไม่เกิดปัญหาทันที แต่การอัปเดตไว้ก่อนคือวิธีที่ปลอดภัยที่สุด เพราะพอเข้าใกล้ช่วงหมดอายุจริง ความเสี่ยงคือระบบอาจตรวจสอบลายเซ็นไม่ผ่านและเกิดอาการบูตผิดปกติได้ แล้วผู้ใช้ต้องทำอะไรบ้าง? 1) ผู้ใช้ทั่วไป: เปิด Windows Update แล้วอัปเดตสม่ำเสมอเป็นหลัก (โดยเฉพาะ Windows 11 ที่มักเปิด Secure Boot เป็นเงื่อนไขสำคัญอยู่แล้ว) 2) เครื่องบางรุ่น: อาจต้องอัปเดต BIOS/UEFI เพิ่มเติมจากเว็บผู้ผลิตเมนบอร์ด/โน้ตบุ๊ก เพื่อให้รองรับใบรับรองใหม่ได้สมบูรณ์ (อันนี้สำคัญมาก เพราะบางครั้งอัปเดตใน Windows อย่างเดียวอาจไม่ครบ) ถ้าจะเช็กคร่าว ๆ ว่า Secure Boot เปิดอยู่ไหม (เผื่อใครอยากรู้ว่าเกี่ยวกับเราหรือเปล่า) ฉันใช้วิธีนี้บ่อย: - กด Start แล้วพิมพ์ “System Information” (ข้อมูลระบบ) - ดูบรรทัด “Secure Boot State” ถ้าขึ้น On คือเปิดใช้งานอยู่ สรุปสั้น ๆ: Secure Boot คือเกราะด่านแรกตอนเปิดเครื่อง และการอัปเดตใบรับรอง/KEK ชุดใหม่ก่อนปี 2026 เป็นการปิดช่องโหว่เชิงโครงสร้างและลดโอกาสเจอปัญหา “เปิดเครื่องไม่ติด” ในอนาคต ถ้าอัปเดตผ่าน Windows Update ได้ก็ทำไว้เลย และอย่าลืมเช็กเฟิร์มแวร์/BIOS ของผู้ผลิตประกอบด้วยเพื่อความชัวร์